Vercel Hacked: The Story Behind the Attack

TL;DR AI
2 min readKey summary
Vercel said a third-party AI tool’s compromised OAuth credentials were used to access an employee’s Google Workspace account.
The attacker escalated privileges inside internal systems and viewed environment variables that were not classified as sensitive.
Vercel said encrypted secret variables were not accessed, and its open-source projects such as Next.js and Turbopack were unaffected.
The incident highlights how third-party OAuth access and weak secret classification can widen the impact of a single compromise.

